Privacy Policy
Version 1.0 — Effective date: 1 April 2026
Compliant with UAE Federal Decree-Law No. 45 of 2021 (PDPL)
1. Who we are
Doobitech ("we", "us", "our") is a SaaS platform operated by a DED-licensed business in Dubai, United Arab Emirates. We provide WhatsApp-based order management software for laundry and dry-cleaning businesses.
Contact: fender.helper@gmail.com
2. What data we collect
From Shop Owners (B2B customers)
- Name, email address, password (hashed)
- Shop name, WhatsApp business number
- Trade license document (PDF or image)
- IP address at time of Terms acceptance
- Billing information (processed by Stripe — we do not store card numbers)
From End Customers (laundry customers)
- WhatsApp phone number
- Name (if provided)
- Pickup address and GPS coordinates
- Order history and services selected
- Preferred language
- Star ratings and comments (if submitted)
Automatically collected
- WhatsApp message logs (sent and received)
- Session data in Redis (30-minute TTL, auto-deleted)
- Usage logs and error reports
3. How we use your data
- To provide and operate the Doobitech platform
- To process orders and send WhatsApp notifications
- To verify trade licenses and maintain compliance
- To process subscription payments via Stripe
- To send service announcements and billing alerts
- To improve platform performance and fix errors
- To comply with UAE legal obligations
We do not sell, rent, or share personal data with third parties for marketing purposes.
4. Legal basis for processing
Under UAE PDPL, we process personal data on the following bases:
- Contract performance — processing necessary to provide the subscription service
- Legal obligation — trade license verification, VAT records, PDPL compliance
- Legitimate interest — platform security, fraud prevention, error monitoring
- Consent — marketing communications (opt-in only)
5. Data storage and security
5.1 Data is stored on Supabase (PostgreSQL) hosted in EU West 2 (London, UK) and Upstash Redis hosted in EU West 1.
5.2 All data is encrypted in transit (TLS 1.2+) and at rest.
5.3 Passwords are hashed using bcrypt and never stored in plain text.
5.4 Access to production data is restricted to authorised Doobitech personnel only.
5.5 Row-Level Security (RLS) is enforced at the database level — each shop can only access its own data.
6. Data retention
| Data type | Retention period |
|---|---|
| Order records | 5 years (UAE commercial law) |
| WhatsApp message logs | 12 months |
| Redis session data | 30 minutes (auto-deleted) |
| Trade license documents | Duration of account + 1 year |
| Billing records | 7 years (UAE tax law) |
| Deleted account data | 30 days after deletion request |
7. Third-party services
Supabase
EU West 2 (London)Database, authentication, file storage
360dialog
EUWhatsApp Business API messaging
Stripe
USA (EU data region)Payment processing (B2B subscriptions)
Vercel
Global CDNApplication hosting and deployment
Upstash
EU West 1Session state and rate limiting
8. Your rights under UAE PDPL
Under Federal Decree-Law No. 45 of 2021, you have the following rights:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a structured format
- Right to object — object to processing based on legitimate interest
To exercise any of these rights, email fender.helper@gmail.com. We will respond within 30 days as required by UAE PDPL.
9. Data breach notification
In the event of a personal data breach, Doobitech will notify the UAE Data Office and affected individuals as soon as possible and in accordance with the timelines required by UAE PDPL.
10. WhatsApp data notice
When customers interact with a shop's WhatsApp bot powered by Doobitech, the first message they receive includes a notice that their data will be processed to handle their laundry order. By continuing to interact with the bot, customers acknowledge this processing.
11. Children's data
Doobitech does not knowingly collect data from individuals under the age of 18. If we become aware that we have collected data from a minor, we will delete it immediately.
12. Changes to this policy
We may update this Privacy Policy periodically. We will notify you via email and WhatsApp at least 14 days before material changes take effect. The current version and effective date are always shown at the top of this page.
13. Contact us
For any privacy-related questions, data requests, or complaints:
Email: fender.helper@gmail.com
We aim to respond to all privacy requests within 5 business days.